Getting Data In

How to detect users using DNS different than organization DNS

abdallahalhabba
New Member

Dear All
Good Day
I need search detect users using DNS different than Organization DNS. Please share me your ideas & suggestion .

Tags (2)
0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @abdallahalhabbash, If richgalloway solved your problem, please remember to "Accept" his answer to award karma points. 🙂

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming you're already collecting network metadata (either from Stream, your proxy server, firewall logs, etc.) then you just need to look for events going to port 53 with a destination IP address not in your network.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...